Rule settings

The following table describes the settings of security posture check rules.
General
Controller mode
Select the controller mode of your device. The default value is set to
Run
.
  • Skip
    : This setting will be skipped.
  • Run
    : The controller mode is set to the
    Run Mode
    or
    Remote Run Mode
    .
Key switch position
Select the position of the keyswitch of your device. The default value is set to
Run
.
  • Skip
    : This setting will be skipped.
  • Remote
    : The keyswitch is set to the
    Remote Run Mode
    .
  • Run
    : The keyswitch is set to the
    Hard Run Mode
    .
Major fault presence
Select the major fault status of your device. The default value is set to
Not present
.
  • Skip
    : This setting will be skipped.
  • Not present
    : There are no faults.
I/O forces presence
Select how the I/O forces capability is handled for your device. The default value is set to
Skip
.
  • Skip
    : This setting will be skipped.
  • Not present
    : I/O forces is disabled.
I/O forces state
Select the status of the I/O forces capability of your device. The default value is set to
Skip
.
  • Skip
    : This setting will be skipped.
  • Inactive
    : I/O forces is inactive.
SFC forces presence
Select how the SFC forces capability is handled for your device. The default value is set to
Skip
.
  • Skip
    : This setting will be skipped.
  • Not present
    : SFC forces is disabled.
SFC forces state
Select the status of the SFC forces capability of your device. The default value is set to
Skip
.
  • Skip
    : This setting will be skipped.
  • Inactive
    : SFC forces is inactive.
Firmware
Major version
Configure the major version of your firmware. Select >= or == to define the version range, and then set the version number.
For example, if the major version is 36:
  • >= 36: Version 36 or later versions are accepted.
  • == 36: Only version 36 is accepted.
Minor version
Configure the minor version of your firmware. Select >= or == to define the version range, and then set the version number.
For example, if the major version and minor version are 36 and 11:
  • >= 36 and >= 11: Version 36.11 or later versions are accepted. For example, 37.12, 38.13, and so on.
  • >= 36 and == 11: Version 36 or later versions with minor version 11 are accepted. For example, 36.11, 37.11, and so on.
  • == 36 and == 11: Only version 36.11 is accepted.
  • == 36 and >= 11: Only version 36 with minor version 11 or later are accepted. For example, 36.11, 36.12, and so on.
Security
Change to detect bit mask
Select how the changes to detect capability is configured. By default, this checkbox is not selected.
If you select this checkbox, enter the bit mask. By default, all items in the
Changes to Detect
list are selected for a controller. The default bit mask is 16#FFFF_FFFF_FFFF_FFFF.
Security authority state
Select the security authority status of your device. The default value is set to
Secured, but not bound to a security authority
.
  • Skip
    : This setting will be skipped.
  • No security
    : Security authority is not set.
  • Secured, but not bound to a security authority
    : Security authority is set in the FactoryTalk Directory, but this security setting is not enabled in your device.
  • Secured and bound to a Primary Security Authority
    : Security authority is set in the FactoryTalk Directory, and this security setting is enabled in your device. Enter the FactoryTalk Directory server name.
  • Secured and bound to a Primary and Secondary Security Authority
    : Security authority is set in two FactoryTalk Directories, and this security setting is enabled in your device. Enter the name for the primary FactoryTalk Directory server.
Controller web pages
Select whether the access to the controller webpages is enabled. The default value is set to
Disabled
.
  • Skip
    : This setting will be skipped.
  • Enabled
    : Access to the controller webpages is enabled.
  • Disabled
    : Access to the controller webpages is disabled.
Safety (Only applicable for safety devices)
Safety application state
Select the safety lock status of the safety application. The default value is set to
Skip
.
  • Skip
    : This setting will be skipped.
  • Locked
    : The safety lock is enabled.
Safety signature
Select the status of the safety signature. The default value is set to
Skip
.
  • Skip
    : This setting will be skipped.
  • Applied
    : The safety signature is applied.
Protect signature in run mode
Select the status of the protect signature in run mode capability. The default value is set to
Skip
.
  • Skip
    : This setting will be skipped.
  • Signature deletion inhibited
    : The protect signature in run mode capability is disabled, and the signature is not allowed to be deleted.
Safety task major fault presence
Select the major fault status of the safety task. The default value is set to
Not present
.
  • Skip
    : This setting will be skipped.
  • Not present
    : There are no faults.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal